<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>
<div dir="auto" style="direction:ltr; margin:0; padding:0; font-family:sans-serif; font-size:11pt; color:black">
External flow does sound like a good starting point. Did think a bit about signatures but not sure if it'd prevent a malicious party from copying the signature from another request. But if the External flow has a chance to compare the values when it returns
 to IdP then it may be able to protect against that. <br>
<br>
</div>
<div dir="auto" style="direction:ltr; margin:0; padding:0; font-family:sans-serif; font-size:11pt; color:black">
I'll take a look at  the Shib-CAS-Authn3 project for inspiration. <br>
<br>
</div>
<div dir="auto" style="direction:ltr; margin:0; padding:0; font-family:sans-serif; font-size:11pt; color:black">
Thanks both! <br>
<br>
</div>
<div dir="auto" style="direction:ltr; margin:0; padding:0; font-family:sans-serif; font-size:11pt; color:black">
<div dir="auto" style="direction:ltr; margin:0; padding:0; font-family:sans-serif; font-size:11pt; color:black">
Get <a href="https://aka.ms/ghei36">Outlook for Android</a></div>
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> Friday, December 7, 2018 4:31:33 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Securely passing</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:11pt;">
<div class="PlainText">* Michael A Grady <mgrady@unicon.net> [2018-12-07 17:21]:<br>
> Yes, Unicon's Shib-CAS-Authn3 extension for the IdP (using a<br>
> separate CAS Server for the authentication) uses that<br>
> ExternalAuthnConfiguration method, and indeed does pass the SP<br>
> entityID across. so that can be done as Peter notes.<br>
<br>
I'm guessing if one was concerned about the authenticity of such<br>
parameters one could add another parameter with a checksum or<br>
signature, since the code on both sides (the component running within<br>
the IDP, the external authentication service) would need to be custom<br>
anyway?<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>